<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:wordpress:super_forms_drag_drop_form_builder:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awordpresssuper_forms_drag_drop_form_builder/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 08:39:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awordpresssuper_forms_drag_drop_form_builder/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Privilege Escalation in Super Forms WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-super-forms-priv-esc/</link><pubDate>Thu, 01 Oct 2026 08:39:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-super-forms-priv-esc/</guid><description>An unauthenticated privilege escalation vulnerability (CVE-2026-15989) in the Super Forms WordPress plugin allows attackers to register administrative accounts via registration form injection.</description><content:encoded><![CDATA[<p>The Super Forms - Drag &amp; Drop Form Builder plugin for WordPress is affected by a critical privilege escalation vulnerability (CVE-2026-15989) in all versions up to and including 6.3.316. The flaw exists within the Register &amp; Login add-on, specifically inside the before_email_success_msg() function. This function improperly handles client-submitted data by whitelisting the 'role' key and passing it directly into the user-data array processed by wp_insert_user().</p>
<p>Because the input is not validated against administrative settings, lacks an allow-list, and performs no capability checks via current_user_can(), unauthenticated attackers can inject the parameter 'role=administrator' into any public Super Forms registration form. This allows the creation of unauthorized accounts with full administrative privileges, granting the attacker complete control over the compromised WordPress instance. Defenders should identify all WordPress installations using Super Forms and ensure they are upgraded to a version beyond 6.3.316 or disable the Register &amp; Login add-on immediately.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target WordPress site utilizing the Super Forms - Drag &amp; Drop Form Builder plugin.</li>
<li>Attacker locates a public-facing registration form created with the Super Forms plugin.</li>
<li>Attacker initiates an HTTP POST request to the form handler, specifying register_login_action='register'.</li>
<li>Attacker injects the 'role=administrator' parameter into the registration form submission data.</li>
<li>The server-side before_email_success_msg() function in the Register &amp; Login add-on accepts the malicious 'role' key without validation.</li>
<li>The system executes wp_insert_user() using the attacker-supplied role data.</li>
<li>A new user account is created with Administrator privileges.</li>
<li>Attacker authenticates with the newly created account to establish persistent administrative access.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to gain full administrative access to affected WordPress installations. This leads to complete site compromise, including the ability to execute arbitrary code (via theme or plugin file uploads), exfiltrate sensitive user data, install backdoors, or redirect site traffic. This vulnerability carries a CVSS v3.1 base score of 9.8.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Update the Super Forms - Drag &amp; Drop Form Builder plugin to a version higher than 6.3.316 immediately.</li>
<li>If an update is unavailable, disable the Register &amp; Login add-on to prevent exploitation of CVE-2026-15989.</li>
<li>Audit the user database for accounts with administrative privileges created unexpectedly after the publication of this advisory (October 1, 2026).</li>
<li>Deploy the provided webserver detection rule to monitor for suspicious registration attempts containing unexpected role parameters.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>web-application</category><category>wordpress</category><category>privilege-escalation</category><category>cve-2026-15989</category></item></channel></rss>